Engineer, harden, and operate large‑scale, multi‑domain Active Directory environments supporting critical business workloads.
Lead Active Directory consolidation and domain rationalization, reducing directory sprawl across enterprise, eCommerce, and business units.
Operate and enhance Virtual Directory services (RadiantLogic) to support federated and multi‑source identity use cases.
Define, implement, and enforce baseline identity security standards across complex, multi‑domain environments.
Design and mature RBAC‑based access models within Active Directory.
Integrate Active Directory with Privileged Identity and Access Management (PIM/PAM) platforms.
Eliminate standing privilege through group‑based, time‑bound, just‑in‑time (JIT) access patterns.
Implement and sustain Tier 0 security posture, including privileged account separation and Privileged Access Workstations (PAW).
Design and operate bi‑directional synchronization between Active Directory and Entra ID, partnering with cloud identity teams for consistent governance.
Improve identity governance and lifecycle accuracy through authoritative attribute synchronization, cross‑tenant governance, automation, documentation, and mentoring of junior engineers.